Skip to main content
CRITICAL

CVE-2023-33241

CVSS v3

9.1

CRITICAL

EPSS Score

1.2 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

Technical details

Published
2023-08-09

Frequently asked questions

What is CVE-2023-33241?

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

Is CVE-2023-33241 actively exploited?

Active exploitation of CVE-2023-33241 has not been confirmed. Its EPSS score was 1.2% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-33241?

CVE-2023-33241 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2023-33241 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key